Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Exhibit

Refer to the exhibit.

```json
{
  "permissions": [
    {
      "permission": "Sensitive Info Types"
    },
    {
      "permission": "Data Classifiers"
    },
    {
      "permission": "Content Explorer"
    }
  ]
}
```

Refer to the exhibit. A compliance administrator is configuring role-based access control (RBAC) in Microsoft Purview compliance portal. Which role group would provide the permissions shown?

⚠ Common exam trap

Test-takers frequently confuse the 'Compliance Administrator' role group with the 'Information Protection' role group, because both involve compliance tasks, but the exhibit specifically lists permissions that map to information protection functions, not broader compliance management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Information Protection

The exhibit displays permissions related to managing sensitivity labels, label policies, and data loss prevention (DLP) rules within Microsoft Purview. The Information Protection role group is specifically designed for administrators who need to configure and manage these information protection features, making it the correct choice as it directly encompasses all the displayed permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Compliance Administrator

    Why it's wrong here

    The Compliance Administrator role group provides broad permissions for managing compliance features across Microsoft 365, including audit logs, eDiscovery, and data lifecycle management. However, it does not inherently grant the specific, granular permissions required to create, modify, or publish sensitivity labels and their associated policies, nor to configure auto-labeling rules. While powerful, it's not the most precise role for direct information protection configuration tasks.

  • ✗

    Security Reader

    Why it's wrong here

    The Security Reader role group is strictly limited to read-only access across various security and compliance features within Microsoft 365. This role allows administrators to view security reports, alerts, and configurations but explicitly prevents any write operations. Therefore, a user assigned to Security Reader cannot create new sensitivity labels, publish label policies, or configure automatic labeling rules, as these actions require modification permissions.

  • ✗

    Data Classification

    Why it's wrong here

    The term 'Data Classification' refers to a capability or a set of permissions related to identifying and categorizing data, rather than being a distinct, assignable role group within the Microsoft Purview compliance portal. While permissions for data classification exist, they are typically bundled within established role groups like 'Information Protection' or 'Compliance Administrator.' It is not a standalone role group that can be directly assigned to users.

  • ✓

    Information Protection

    Why this is correct

    The Information Protection role group is specifically designed to manage all aspects of sensitivity labels and related information protection features within the Microsoft Purview compliance portal. Members of this role group possess the necessary permissions to create, edit, publish, and delete sensitivity labels, configure label policies, and set up automatic labeling rules. This role provides the precise administrative capabilities required for comprehensive information protection management.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.